ToolScout
Security update ยท 25 September 2026

GitHub adds fresh authentication for high-impact enterprise actions

GitHub Enterprise Cloud can now require a fresh identity check before members create tokens, edit webhooks or perform other sensitive account actions.

What changed

GitHub has released proof of presence in public preview for Enterprise Managed Users on GitHub Enterprise Cloud and GitHub Enterprise Cloud with Data Residency when Microsoft Entra ID is used for SSO through SAML or OIDC. Administrators can require interactive re-authentication or an MFA challenge immediately before selected high-impact actions.

Examples include creating a token, editing webhooks, changing organization security settings and viewing recovery codes. GitHub sends the member back to the identity provider to satisfy the configured policy before allowing the action. After a successful challenge, the proof remains valid for high-impact actions in that browser session for two hours.

Why it matters

A valid session or long-lived token is not always enough evidence that the intended person is still controlling the account. Proof of presence gives enterprise buyers another control against compromised sessions, stolen credentials and agents attempting sensitive actions without a fresh human identity check.

Buyer takeaway

For security-sensitive organizations already standardized on Entra ID and managed GitHub users, this adds a useful control at the moment risk is highest rather than relying only on login-time authentication. The current preview is narrowly scoped, so buyers using other identity providers or unmanaged accounts should not assume the capability is available to them yet.

Primary source: GitHub Changelog. ToolScout writes independent summaries and analysis. Affiliate relationships do not determine coverage.
More software news